Skip to main content

Help us improve the Digital Marketplace - send your feedback

INCLINE IT LIMITED

Vestalet

Our solution, Vestalet, simplifies how people rent, buy, and exchange homes. It is a secure, cloud-based platform that connects housing providers and customers through intuitive digital services, streamlining property listings, enquiries, and tenant engagement to deliver a transparent, modern housing experience via browser and dedicated mobile app.

Features

  • Unified digital platform for lettings, sales and mutual exchanges
  • Web-based access via desktop and mobile devices
  • Intelligent property search and matching with configurable filters
  • Tenant self-service for registrations, expressions of interest and exchanges
  • Provider dashboard for managing listings, enquiries and applicant data
  • Automated notifications, reminders and status updates
  • Secure cloud-hosted platform aligned with UK data protection requirements
  • Configurable workflows to support lettings and sales schemes
  • API-enabled integration with housing management and CRM systems
  • Scalable architecture to support organisations of varying sizes

Benefits

  • Property lettings, sales and exchange processes through a single platform
  • Reduces administrative effort through automation and self-service
  • Improves customer experience with clear, transparent digital journeys
  • Accelerates matching of applicants to suitable homes
  • Increases operational efficiency for housing and local authority teams
  • Enhances data consistency across housing and customer systems
  • Supports digital transformation and modern service delivery
  • Improves accessibility with mobile-friendly, intuitive design
  • Scales easily to meet changing demand and portfolio size
  • Builds trust through secure handling of customer and property data

Pricing

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@incline-it.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 1 6 8 4 6 9 8 2 7 3 2 9 6 8

Contact

INCLINE IT LIMITED Sales
Telephone: 0845 330 3225
Email: sales@incline-it.com

About your service

Service categories

Applications

Customer relationship management

  • Customer service
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Support is supplied remotely. Standard Support hours are Monday to Friday 8:00am to 6:00pm, however enhanced Support Hours can be purchased if required.
System requirements
Internet or data connection

User support

Email or online ticketing support
Yes
Support response times
Critical incidents - Immediate High - 10 Minutes Medium - 1 Hour Low - 4 Hours Very Low - 1 Day
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
WCAG 2.2 AA
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide a tiered support model aligned to a defined Incident Response Matrix. Priority 1 (Critical) incidents receive immediate response with a one-hour target resolution inside business hours and two hours outside. Priority 2 (High) incidents receive a 10-minute response and four-hour resolution. Priority 3 (Medium) incidents receive a one-hour response and eight-hour resolution. Priority 4 (Low) incidents receive a four-hour response and 24-hour resolution, while Priority 5 (Very Low) incidents receive a one-day response and one-week resolution. All support levels are included within our standard support service; there are no uplifted charges for higher-priority incidents. Support outside of business hours is available at an extra cost. We provide access to a technical and support staff as the required to assess and resolve the support issue. The staff offer proactive guidance, environment familiarity, and escalation management to ensure efficient issue resolution and ongoing operational assurance.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Customers are pre-set in the solution, meaning that customers can log in and claim access to their account. Users must complete some initial checks to ensure that they truly represent the customer.
Once inside the solution, we guide the users through the onboarding journey with videos, documentation and a call if the need arises. Configuration takes less than an hour. Data imports are available at the appropriate points and documentation is available to support their use.
Agentic AI will be available in the future to support the onboarding and ongoing maintenance of the solution.
New features will be regularly released and additional guidance will be provided for each release.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
  • Other
Other documentation formats
Videos
End-of-contract data extraction
The service is a pay-as-you-go service and data can be exported by the users at any point.
In the event that the solution is not utilised for 3 months then we will reach out to the customers. In the event that the solution is not accessed for 6 months then we will suspend the account.
End-of-contract process
Upon termination, the account is suspended. As the solution is intended only for social housing providers, we maintain all social housing providers in the solution ready for use.
Extracting data is at no charge.
Documentation accessibility standard
WCAG 2.2 AA

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
Yes
Compatible operating systems
  • Android
  • IOS
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The configuration and management of Vestalet for administrators is accessed by browser only. The Vestalet end user application can be accessed via Web Browser on devices or via the dedicated iOS or Android Mobile App.
Service interface
Yes
User support accessibility
WCAG 2.2 AA
Description of service interface
Vestalet provides a browser-based, intuitive service interface that enables admin users to manage connectivity and customisation options from a single workspace.
Accessibility standards
WCAG 2.2 AA
Accessibility testing
We have not conducted any interface testing of the service interface with users of assistive technology at this time.
API
No
Customisation available
Yes
Description of customisation
Users can customise Vestalet to align with their organisation’s policies, and operational processes through a range of configurable administrative features.

What can be customised: Customisation includes creating allocations and sales policies aligned to operational policies.

How users can customise: Customisation is completed via the configuration options in the secure Admin interface. Admin users configure settings using built-in tools.

Who can customise: Customisation is restricted to authorised administrative users within the customer organisation. Admin access is role-based and secured using Single Sign-On (SSO) linked to the organisation’s identity provider, ensuring only approved staff can make changes.

Scaling

Independence of resources
Our serverless architecture ensures total performance isolation by scaling compute resources horizontally for every request, preventing any single user from monopolising capacity. We utilise Valkey as a high-speed caching and rate-limiting layer, shielding the core Postgres database from traffic spikes and ensuring millisecond response times for administrators, with the presentation layer for end users all cached in AWS CloudFront

Furthermore, by offloading intensive analytical queries to S3, we "air-gap" heavy reporting from the live bidding engine. This multi-layered approach, combining elastic scaling, distributed caching, and data decoupling, guarantees consistent, lightning-fast performance for all users, regardless of aggregate platform demand.

Analytics

Service usage metrics
Yes
Metrics types
Our platform delivers comprehensive metrics across four key pillars, these would be accessible via AWS Athena which can be accessed from PowerBI and other industry standard tools.

Demand & Bidding: Monitor applicant distribution by priority band, bid density per property, and digital engagement levels.

Operational Efficiency: Track void turnaround times, refusal reasons, and bid-to-let ratios to streamline allocations.

Social Impact: Report on equality, diversity, and homelessness prevention to meet regulatory requirements (e.g., CORE).

Strategic Trends: Use longitudinal data to forecast long-term housing demand and supply alignment.

This architecture ensures high-performance reporting without impacting live system stability.
Reporting types
  • API access
  • Real-time dashboards
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Staff screening not performed
Government security clearance
None

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
No
Datacentre security standards
Managed by a third party
Penetration testing frequency
At least once a year
Penetration testing approach
‘IT Health Check’ performed by a CREST-approved service provider
Protecting data at rest
Physical access control, complying with CSA CCM v4.0
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Data Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Degaussing
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
Data exports are available within the solution as standard and available to users of the solution either in an output format or via an API.
Data export formats
  • CSV
  • ODF
  • Other
Other data export formats
API
Data import formats
  • CSV
  • ODF
  • Other
Other data import formats
API

Data-in-transit protection

Data protection between buyer and supplier networks
  • Private network or public sector network
  • TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Customer Hub is hosted with Amazon Web Services who have a 99.99% uptime SLA. It is based in AWS eu-west-2, which is the London Region. The service is spread across multiple availability zones for resilience. Our Terms and Conditions detail the process if guaranteed levels of availability are not met.
Approach to resilience
This information is available on request.
Outage reporting
If an outage were to occur, our customers would receive an email alert.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
Access restrictions in management interfaces and support channels
We enforce a Zero Trust model using Role-Based Access Control (RBAC) to ensure staff only access data essential to their role. Management interfaces are secured via Multi-Factor Authentication (MFA)

Every administrative action is captured in immutable audit logs streamed to S3, enabling forensic oversight via Athena. By integrating with client Identity Providers (SSO), we guarantee immediate access revocation, maintaining a rigorous security posture across all management and support touchpoints.
Access restriction testing frequency
At least once a year
Management access authentication
Multi-Factor Authentication (MFA)

Audit information for users

Access to user activity audit information
Users contact the support team to get audit information
How long user audit data is stored for
At least 12 months
Access to supplier activity audit information
Users contact the support team to get audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
At least 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
As an AWS Advanced Tier Partner, we integrate ISO 27001 principles, Confidentiality, Integrity, and Availability directly into our cloud-native architectures. We do not just deploy technology; we govern it through risk assessments and automated guardrails that satisfy both technical auditors and regulatory bodies. Our Non-Profit Competency allows us to tailor this high-level security to the unique constraints of the sector. We provide non-profits with enterprise-grade security that is cost-optimized, utilizing AWS grants and ethical licensing models to ensure that mission-critical funds are preserved. By coupling ISO 27001 governance with specialized AWS validations, we provide security aligned to risk based and technical controls and assessments, ensuring trust and data privacy. This holistic approach transforms compliance from a hurdle into a strategic asset, enabling organisations to scale their social impact on a globally recognized, secure foundations.
Software Security Code of Practice
No

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
We track all service components from deployment to retirement using Infrastructure as Code (IaC) templates and AWS Config, which maintains a continuous inventory and version history of all resources. Every change undergoes a mandatory Security Impact Assessment via our CI/CD pipeline, where automated tools perform Static Code Analysis and check against the CIS AWS Foundations Benchmark v5.0.0. High-impact changes require a manual peer review and "Security Sign-off" before merging. This ensures that every modification is documented, authorized, and validated for risk, meeting CSA CCM v4 and ISO 27001 change control standards.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We assess potential threats through a continuous lifecycle: pre-deployment Static Code Analysis (SAST) catches vulnerabilities early, while daily AWS Inspector scans monitor our live infrastructure. Every two weeks, we conduct AWS Security Hub reviews against the CIS AWS Foundations Benchmark v5.0.0 to identify misconfigurations. For deep validation, we perform annual Penetration Tests and secondary tests for all Major Releases. Our risk-based patching SLA ensures Critical vulnerabilities are addressed within 14 days, High within 30 days, and lower risks during standard maintenance. Threat intelligence is sourced directly from AWS GuardDuty, CVE databases, and CIS advisory feeds.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
We proactively identify compromises using Amazon GuardDuty for intelligent threat detection and AWS Security Hub, which provides bi-weekly posture reviews against CIS v5.0.0. Daily AWS Inspector scans and annual penetration tests act as early-warning systems for exploitable gaps. Upon detecting a potential compromise, we initiate our Incident Response Plan, isolating affected resources (e.g., via Security Groups) and performing root-cause analysis using AWS CloudTrail logs. We commit to a 4-hour response time for critical security alerts, with 24/7 automated paging for critical-severity findings to ensure rapid containment and minimal business impact for customers who require 24/7 support.
Incident management type
Supplier-defined controls
Incident management approach
We maintain a formal Incident Response Plan with pre-defined playbooks for common events like unauthorized AWS access or malware detection, triggered by AWS Security Hub (CIS v5.0.0) and GuardDuty. Users report incidents via a dedicated Security Portal or an internal 24/7 emergency alias. We prioritize containment within 4 hours for critical events. Following resolution, we provide Post-Incident Reports (PIRs) to stakeholders, detailing the root cause analysis from AWS CloudTrail, impact assessment, and remediation actions. This process aligns with ISO 27001 and CCM v4 (SEF domain) for continuous security improvement
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
No
Free trial available
No

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
1%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
10%
Between £1,000,001 and £2,500,000
15%
Between £2,500,001 and £5,000,000
15%
Over £5,000,001
15%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Alcumus ISOQAR
ISO/IEC 27001 accreditation date
Saturday 6 March 2021
What the ISO/IEC 27001 doesn’t cover
We have completed statement of applicability with 100% coverage to the standard.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Alcumus ISOQAR
ISO 9001 accreditation date
Monday 13 July 2020
What the ISO 9001 doesn’t cover
We have 100% coverage under the QMS
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
6efd269c-74fa-4ea4-915d-0025386416c3
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
Yes
Any other security certifications
ISO 27001

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities that demonstrate a collaborative way to work with a diverse range of businesses as part of the supply chain
    • Understanding of local demographics, needs and opportunities for the co-design of the goods, services and works to be delivered under the contract
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Working conditions which promote an inclusive working environment and promote retention and progression
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at sales@incline-it.com. Tell them what format you need. It will help if you say what assistive technology you use.